Publication Date: 2013-05-24
Last Update: 2019-12-10
Current Version: V1.2
CVSS v3.1 Base Score: 7.6

Affected Product and Versions Remediation
SCALANCE X-200 switch family (incl. SIPLUS NET variants):
Versions < V5.0.0 for CVE-2013-3633 and versions < V4.5.0 for CVE-2013-3634
Update to V5.0.0 (released in 2013), or any later version (currently V5.2.4)
https://support.industry.siemens.com/cs/document/109767965
SCALANCE X-200IRT switch family (incl. SIPLUS NET variants):
All versions < V5.1.0
Update to V5.1.0 (released in 2013), or any later version (currently V5.4.2)
https://support.industry.siemens.com/cs/document/109763309

CVSS v3.1 Base Score 7.6
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H/E:P/RL:O/RC:C
CWE: CWE-603: Use of Client-Side Authentication

CVSS v3.1 Base Score 7.3
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
CWE: CWE-287: Improper Authentication

https://www.siemens.com/cert/advisories